-Dovecot 2.1: Almost as good as dovecot 2.2. Does not support ssl\_prefer\_server\_ciphers

-

-\paragraph*{Limitations}\mbox{}\\

-

-Dovecot currently does not support disabling TLS compression. Furthermore, DH parameters

-greater than 1024bit aren't possible. The most recent version 2.2.7 of Dovecot implements

-configurable DH parameter length

-\footnote{\url{http://hg.dovecot.org/dovecot-2.2/rev/43ab5abeb8f0}}.

-

-\subsubsection{cyrus-imapd (based on 2.4.17)}

-

-\paragraph*{imapd.conf}\mbox{}\\

-

-To activate SSL/TLS configure your certificate with

-\begin{lstlisting}[breaklines]

- tls_cert_file: .../cert.pem

- tls_key_file: .../cert.key

-\end{lstlisting}

-

-Do not forget to add necessary intermediate certificates to the .pem file.\\

-

-Limiting the ciphers provided may force (especially older) clients to connect without encryption at all! Sticking to the defaults is recommended.\\

-

-If you still want to force strong encryption use

-\begin{lstlisting}[breaklines]

- tls_cipher_list: <...recommended ciphersuite...>

-\end{lstlisting}

-

-cyrus-imapd loads hardcoded 1024 bit DH parameters using get\_rfc2409\_prime\_1024() by default. If you want to load your own DH parameters add them PEM encoded to the certificate file given in tls\_cert\_file. Do not forget to re-add them after updating your certificate.\\

-

-To prevent unencrypted connections on the STARTTLS ports you can set

-\begin{lstlisting}[breaklines]

- allowplaintext: 0

-\end{lstlisting}

-This way MUAs can only authenticate after STARTTLS if you only provide plaintext and SASL PLAIN login methods. Therefore providing CRAM-MD5 or DIGEST-MD5 methods is not recommended.\\

-

-\paragraph*{cyrus.conf}\mbox{}\\

-

-To support POP3/IMAP on ports 110/143 with STARTTLS add

-\begin{lstlisting}[breaklines]

- imap cmd="imapd" listen="imap" prefork=3

- pop3 cmd="pop3d" listen="pop3" prefork=1

-\end{lstlisting}

-to the SERVICES section.\\

-

-To support POP3S/IMAPS on ports 995/993 add

-\begin{lstlisting}[breaklines]

- imaps cmd="imapd -s" listen="imaps" prefork=3

- pop3s cmd="pop3d -s" listen="pop3s" prefork=1

-\end{lstlisting}

-

-

-\paragraph*{Limitations}\mbox{}\\

-

-cyrus-imapd currently (2.4.17, trunk) does not support elliptic curves. ECDHE will not work even if defined in your cipher list.\\

-

-Currently there is no way to prefer server ciphers or to disable compression.\\

-SMTP usually uses opportunistic TLS. This means that an MTA will accept TLS connections when asked for it during handshake but will not require it. One should always support incoming opportunistic TLS and always try TLS handshake outgoing.\\

-It is not advisable to restrict the default cipher list for MSA mode if you don't know all connecting MUAs. If you still want to define one please consult the Exim documentation or ask on the exim-users mailinglist.\\

-% Exim maintainers do not recommend to change default ciphers

-% I think we shouldn't, too

-%use:

-%\begin{lstlisting}[breaklines]

-% tls_require_ciphers = <...recommended ciphersuite...>

-%\end{lstlisting}

-

-The cipher used is written to the logfiles by default. You may want to add

-don't forget to add intermediate certificates to the .pem file if needed.\\

-\\

-Tell Exim to advertise STARTTLS in the EHLO answer to everyone:

-\begin{lstlisting}[breaklines]

- tls_advertise_hosts = *

-\end{lstlisting}

-

-Listen on smtp(25) port only

-\begin{lstlisting}[breaklines]

- daemon_smtp_ports = smtp

-\end{lstlisting}

-

-It is not advisable to restrict the default cipher list for opportunistic encryption as used by SMTP. Do not use cipher lists recommended for HTTPS! If you still want to define one please consult the Exim documentation or ask on the exim-users mailinglist.\\

-% Exim maintainers do not recommend to change default ciphers

-% We shouldn't, too

-%use:

-%\begin{lstlisting}[breaklines]

-% tls_require_ciphers = <...recommended ciphersuite...>

-%\end{lstlisting}

-

-If you want to request and verify client certificates from sending hosts set

-\begin{lstlisting}[breaklines]

- tls_verify_certificates = /etc/pki/tls/certs/ca-bundle.crt

- tls_try_verify_hosts = *

-\end{lstlisting}

-

-tls\_try\_verify\_hosts only reports the result to your logfile. If you want to disconnect such clients you have to use

-\begin{lstlisting}[breaklines]

- tls_verify_hosts = *

-\end{lstlisting}

-

-The cipher used is written to the logfiles by default. You may want to add

-Client mode settings have to be done in the configuration section of the smtp transport (driver = smtp).

-

-If you want to use a client certificate (most server certificates can be used as client certificate, too) set

-\begin{lstlisting}[breaklines]

- tls_certificate = .../cert.pem

- tls_privatekey = .../cert.key

-\end{lstlisting}

-This is recommended for MTA-MTA traffic.\\

-

-%If you want to limit used ciphers set

-%\begin{lstlisting}[breaklines]

-% tls_require_ciphers = <...recommended ciphersuite...>

-%\end{lstlisting}

-% Exim Maintainers do not recommend ciphers. We shouldn't do so, too.

-Do not limit ciphers without a very good reason. In the worst case you end up without encryption at all instead of some weak encryption. Please consult the Exim documentation if you really need to define ciphers.

-Note: +all is misleading here since OpenSSL only activates the most common workarounds. But that's how SSL\_OP\_ALL is defined.\\

-

-You do not need to set dh\_parameters. Exim with OpenSSL by default uses parameter initialization with the "2048-bit MODP Group with 224-bit Prime Order Subgroup" defined in section 2.2 of RFC 5114 (ike23).

-If you want to set your own DH parameters please read the TLS documentation of exim.\\

-

-

-

-\paragraph*{GnuTLS}\mbox{}\\

-

-GnuTLS is different in only some respects to OpenSSL:

-\begin{itemize}

-\item tls\_require\_ciphers needs a GnuTLS priority string instead of a cipher list. It is recommended to use the defaults by not defining this option. It highly depends on the version of GnuTLS used. Therefore it is not advisable to change the defaults.

-\item There is no option like openssl\_options

-\end{itemize}

-

-\paragraph*{Exim string expansion}\mbox{}\\

-

-Note that most of the options accept expansion strings. This way you can eg. set cipher lists or STARTTLS advertisment conditionally. Please follow the link to the official Exim documentation to get more information.

-

-\paragraph*{Limitations}\mbox{}\\

-

-Exim currently (4.82) does not support elliptic curves with OpenSSL. This means that ECDHE is not used even if defined in your cipher list.